CVE-2025-11244

T

he Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the `pp_get_ip_address()` function when the "Use transients" feature is enabled. This makes it possible for attackers to bypass authorization by spoofing these headers with the IP address of a legitimately authenticated user, granted the "Use transients" option is enabled (non-default configuration) and the site is not behind a CDN or reverse proxy that overwrites these headers.

Configurations

No configuration.

History

25 Oct 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-25 06:15

Updated : 2025-10-27 13:20


NVD link : CVE-2025-11244

Mitre link : CVE-2025-11244

CVE.ORG link : CVE-2025-11244


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization